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Data protection 
as a service 


Enabling your data 
protection compliance 


Data protection 
as a service 


Data Protection regulations and 
laws, such as the GDPR, ePrivacy, 
Data Protection Act 2018 etc. along 
with other data protection risks and 
emerging regulations, continue to 
impose obligations on our clients. 


At Grant Thornton, our Data 
Protection as a Service (DPaaS) 
offering is designed to meet these 
challenges reducing the data 
protection risk exposure of our 
clients. 


Our DPaas utilises the collective 
expertise of our data protection 
and cyber security teams, helping 
clients to achieve and sustain data 
protection compliance. 


We adopt a highly collaborative 
approach, providing you with: 
e a dedicated data protection team 
for expert advice; 
oversight of key processes and 
artefacts; 
resource capability to develop 
data protection artefacts; 
incident and subject right request 
response capabilities; 
strategic guidance on key 
data protection decisions and 
activities; 
regular compliance checks; and 
reporting to senior management. 


Integrated service: 
sharing our wealth 
of data protection 
expertise 


Ongoing support 

You will have access to our 
dedicated data protection phone 
helpline for data protection advice 
and support. We will assist you 
when taking positions on discreet 
data protection challenges and 
provide as required expert advice. 


On demand resourcing 

Our team of data protection 

professionals can boost the capacity 

of your data protection team as required. 

Primarily used when dealing with subject 

rights requests and incident responses. It 

is also used for 

ad hoc project work including: 

e policy writing and reviewing; 

* process and procedure creation and 
review; 

* operating model design and 
implementation; 

e third party management; 

* Data Privacy Impact Assessment (DPIA) 
delivery; and 

+ IT systems reviews and data mapping. 


Understanding your risks and controls 
Our initial onboarding phase consists of an 


assessment of your current data protection 


compliance and the provision of key data 


protection artefacts to strengthen your data 


protection controls. 


FN 


Understanding 
risks and 
controls 


Future 
changes 


Future changes to 

data protection landscape 

We work with you to develop a strategic 

roadmap informed by your data protection 

risk appetite and upcoming developments 

such as: 

e the ePrivacy Regulation; 

* adequacy decisions; 

e data protection case law; 

+ European Data Protection Board (EDPB) 
clarifications and guidelines; and 

e data subject expectations. 


Oversight 

Our team provides ongoing oversight 

of key data protection artefacts and 
processes, through regular compliance 
checks and assessments of projects and 
third party vendors. 


Access to expertise 

You will have access to a dedicated 

team of experts for data protection 

advice and support. Our experienced 

team includes qualified and certified: 

* privacy professionals, managers and 
technologists; 

e Data Protection Officers 

e IT security managers; 

* systems auditors; 

e systems security professionals; 

e PRINCE2/PMP practitioners. 


Key contacts for our 
dedicated team include: 


Mike Harris Shane Carrick, 

Partner, Advisory FIP, CIPP/E, CIPM, 

T +353 (0)1 436 6503 CIPT, FCCA, PMP 

E mike.harris@ie.gt.com Head of Data Protection 


Client Services 
T +353 (0)1 680 5936 
E shane.carrick@ie.gt.com 


Offices in Dublin, Belfast, Cork, 
Galway, Kildare, Limerick and Longford. 
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